CVE-2022-23043 Information
Jun 07, 2022
cve
Description
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new ‘File/MIME Types’ using the ‘.phar’ extension. Then an attacker can upload a malicious file intercept the request and change the extension to ‘.phar’ in order to run commands on the server.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://fluidattacks.com/advisories/simone/ https://github.com/TribalSystems/Zenario/releases/tag/9.2.55826
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: